CVE-2008-4167 Information

Description

useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication which allows remote attackers to (1) add or (2) remove an Administrator account.

Reference

http://secunia.com/advisories/31774 http://securityreason.com/securityalert/4282 http://www.securityfocus.com/bid/31161 https://exchange.xforce.ibmcloud.com/vulnerabilities/45119 https://www.exploit-db.com/exploits/6437

Share on: